Process-cycle reviews, not a generic checklist
Internal audit scoped around how the business actually operates — the cycles where risk concentrates, not a template applied uniformly regardless of what the company does.
Procure-to-pay
Vendor selection and master-data controls, purchase-requisition approval, three-way match (invoice, PO, receipt), and payment approval and authorisation.
Order-to-cash
Customer master and order-entry controls, invoice generation accuracy, segregation of duties, and order-approval workflow including credit checks.
Fixed assets & capex
Approval and authorisation for acquisitions, physical verification and tagging, disposal processes, and ITC applicability on additions.
Inventory & production
Inventory records and movement reports, sample-based physical verification, valuation review, and — where relevant — production-process and quality-standard walkthroughs.
Payroll & treasury
Hiring and attendance-tracking controls, statutory compliance (PF/ESI/gratuity), treasury policy review, cash-flow forecasting and bank reconciliation.
Statutory compliance & financial reporting
GSTR-2A reconciliation with books, TDS compliance, and review of the month-end/year-end financial close process.
IFC / ICFR evaluation
Entity-level controls and process-level Risk & Control Matrices, evaluated across the cycles where financial reporting risk actually sits.
Order-to-cash
Procure-to-pay
Inventory & manufacturing
Fixed assets & capex
Payroll & employee costs
Treasury, forex & related parties
Financial close & reporting
IT general controls
Six patterns we look for first
Recurring gaps we assess for, drawn from our internal-audit and IFC engagement experience.
Culture & risk awareness
Risk awareness not consistently embedded across management and staff, allowing lapses to go unnoticed.
IT general controls
Gaps in access management, change management and system configuration exposing key systems to error or unauthorised access.
Maker-checker controls
Secondary review not consistently applied across critical transaction cycles.
Segregation of duties
Overlapping roles and unclear delegation of authority increasing exposure to unchecked transactions.
Policies & documentation
Absence of formally documented SOPs and delegation-of-power matrices creating inconsistent execution.
Fraud monitoring
Limited ability to proactively detect anomalies or irregular transactions without continuous monitoring.
Beyond process audits
ITGC / ITAC
Assessment of ERP systems, IT infrastructure, cyber security and IT general/application controls.
Fixed asset verification
Comprehensive physical verification, reconciliation with registers, and obsolescence assessment; inventory verification and costing review, including physical stock observation.
Forensic audit
Detection of fraud, misappropriation and misconduct, including digital forensics where required.
Contact
For queries relating to internal audit, IFC/ICFR or risk advisory, please get in touch.